Wednesday, July 26, 2017

Cisco IOS XE Software Autonomic Networking Infrastructure Certificate Revocation Vulnerability

A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been revoked.

The vulnerability exists because the affected software does not transfer certificate revocation lists (CRLs) across Autonomic Control Plane (ACP) channels. An attacker could exploit this vulnerability by connecting an autonomic node, which has a known and revoked certificate, to the autonomic domain of an affected system. A successful exploit could allow the attacker to insert a previously trusted autonomic node into the autonomic domain of an affected system after the certificate for the node has been revoked.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://ift.tt/2uXoce4 A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been revoked.

The vulnerability exists because the affected software does not transfer certificate revocation lists (CRLs) across Autonomic Control Plane (ACP) channels. An attacker could exploit this vulnerability by connecting an autonomic node, which has a known and revoked certificate, to the autonomic domain of an affected system. A successful exploit could allow the attacker to insert a previously trusted autonomic node into the autonomic domain of an affected system after the certificate for the node has been revoked.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
http://ift.tt/2uXoce4
Security Impact Rating: Medium
CVE: CVE-2017-6664

from Cisco Security Advisory http://ift.tt/2uXoce4

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.